Also known as: Storm-0978, Tropical Scorpius, UNC2596, APT34, Smoke Sandstorm, Imperial Kitten, Earth Preta, Stately Taurus, APT28, UNC1549, Yellow Liderc, CASCADE PANDA, YoroTrooper, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, TA446, GOSSAMER BEAR, TAG-53, IRON FRONTIER, UNC4057, COLD RELIC, Desert Falcon, Arid Viper, Bearded Barbie, Two-tailed Scorpion, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar
TA455—also known by aliases such as Storm‑0978, APT28, and Imperial Kitten—has been linked to a persistent, multi‐campaign espionage effort that targets aerospace, defense, finance, and many other sectors across the globe. In its latest “Iranian Dream Job” operation, the group leveraged LinkedIn spear phishing links that entice victims with enticing job opportunities, delivering malicious ZIP files that contain an obfuscated executable (secur32.dll). The payload exploits a WinRAR zero‑day (CVE‑2025‑8088) to silently extract and deploy a multi‑stage backdoor portfolio including SnapBot variants, RustyClaw, Mythic agents, MiniJunk, MiniBrowse, and other custom malware. TA455’s operations also demonstrate extensive defense‑evasion techniques. The group uses DLL hijacking, NTFS alternate data streams to hide code, and malicious JavaScript that exploits CVE‑2018‑6065 in Chrome to redirect victims through Cloudflare‐like domains before downloading encrypted binaries from command‑and‑control servers. In addition, they deploy PowerShell loaders with heavily obfuscated shellcode and use hardened Cobalt Strike beacons that employ custom malleable profiles. A notable aspect of TA455’s strategy is the intentional mimicry of North Korean Lazarus group TTPs, which introduces attribution ambiguity and slows investigative response. The group also extends its reach through multi‑stage infection chains—such as weaponized DOCX files exploiting CVE‑2017‑0199/CVE‑2017‑11882 and LNK/HTA loader archives—to achieve persistence across varied environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA455 is an Iranian state-sponsored APT that conducts sophisticated espionage campaigns against aerospace, defense and a wide range of critical sectors worldwide. Using deceptive job‑offer lures, spear phishing, zero‑day vulnerabilities and tailored backdoors, the group routinely mimics tactics of rival actors to mislead attribution efforts.
Goals & Targeting
TA455’s overarching mission is espionage, focused on acquiring privileged information from adversary governments, defense contractors and critical infrastructure operators. By disguising its operations as those of well‑known criminal or state actors and exploiting high‑value sectors like aerospace and telecommunications, the group seeks to infiltrate both technical systems and human resources, leveraging deceptive recruitment tactics to gain insider footholds.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA455’s campaigns are executed at a brisk pace, utilizing multiple infection vectors across more than 30 target countries. The group systematically builds multi‑stage pipelines that begin with spear‑phishing lures (job offers or software updates), advance through zero‑day exploits and malicious archive delivery, and culminate in persistent backdoor installation. Operations such as the Dream Job Campaign, Operation FrostBeacon targeting Russian B2B firms, and SHADOW‑VOID‑042 showcase a pattern of exploiting public or private sector weaknesses and leveraging decoy websites that mimic legitimate services. These campaigns demonstrate a clear strategic intent: to obtain classified information from high‑value industrial and governmental targets while masking their footprints by replicating the TTPs of rival threat actors. Operational tempo is characterized by rapid iteration—new spear-phishing templates, updated payloads, and continuous changes in command‑and‑control domains. Victims span defense contractors, aerospace manufacturers, financial institutions, telecommunications operators, and non‑profits, with a significant focus on European, Asian, and North American entities. Notable past operations include the Iranian Dream Job Campaign (LinkedIn spear phishing delivering WinRAR zero-day payloads), and Operation FrostBeacon which leveraged weaponized DOCX files to infect Russian B2B firms. The group’s consistent use of multi‑layered infection stages suggests a focus on resilience against detection across diverse environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information consolidates multiple open‑source reports and technical analyses, yielding a moderate confidence assessment. Evidence for core capabilities (spear phishing, zero‑day exploitation, backdoor deployment) is well‑documented, but attribution claims are complicated by the group’s deliberate mimicry of rival actors such as Lazarus and overlapping tool families with other Iranian state sponsors. Key gaps remain in the precise timeline of activity, comprehensive IOC coverage across all campaigns, and internal evidence confirming every listed TTP. Continuous monitoring and cross‑validation against additional threat intelligence feeds are recommended to refine this assessment.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics